Re: splashd Not Redirecting

"Wilson Hernandez - MSD, S. A." <[email protected]> Tue, 18 Nov 2008 19:52:09 -0400
Newsgroups gmane.network.nocat
Organization MSD, S. A.
Message-ID <[email protected]>
Colin,

I am running the gateway on Debian Etch, no radius server. Receiving 
wireless and wired connections from a Linksys Router (WRT54G) with 
dd-wrt but, this router is not running nocat, Can it be run like this?

 I do not need authentication of any type only a splash page where user 
must accept an agreement and proceed to the Internet.

When I try to access the internet from the LAN I get this (It captures 
but it doesn't get redirected to the page the user first requested):

Message: Read 42 config items from /usr/local/etc/nocat.conf
Message: initializing static splash page
Message: Got command /usr/local/libexec/NoCatSplash/initialize.fw from 
action ResetCmd
Message: starting main loop
Message: Captured peer 192.168.2.100
Message: Splashed peer 192.168.2.100
Message: Checking peers for expiration
Message: Checking peers for expiration
Message: Checking peers for expiration
Message: Checking peers for expiration
Message: Accepting peer 192.168.2.100
Message: Got command /usr/local/libexec/NoCatSplash/access.fw permit 
00:2A:78:3D:58:A7 192.168.2.100 Public from action PermitCmd
Message: Captured peer 192.168.2.100
Message: Splashed peer 192.168.2.100

I created a splash.html:

</p>
    <input type="hidden" name="redirect" value="$redirect">
    <input type="hidden" name="accept_terms" value="yes">
    <input type="hidden" name="mode_login">
    <input type="submit" value="enter">
</form>
  <p><img src="/images/auth_logo.gif" width="112" height="35">
<p>

Here's my nocat.conf file:

##########Nocat.conf file#############
Verbosity       10

##### Gateway application settings.
#
# GatewayName -- The name of this gateway, to be optionally displayed
#   on the splash and status pages. Any short string of text will do.
#
GatewayName    Trahersa NoCat Network

##
#
# GatewayMode -- Determines the mode of operation of the gateway. Possible
#   values are:
#  
#   Open    - Simply require a user to view a splash page and accept
#            a use agreement.
#
# Only Open mode is currently supported.
#
GatewayMode    Open

##
# GatewayLog -- Optional.  If unset, messages will go to STDERR.
# (currently unused!)
#
# GatewayLog    /var/log/nocat.log

##
# LoginTimeout - Number of seconds after a client's last
#   login/renewal to terminate their connection. Probably
#   don't want to set this to less than 60 or a lot of
#   bandwidth is likely to get consumed by the client's
#   renewal attempts.
#
# For Open Mode portals, you probably want to comment out
#   the preceding and set LoginTimeout to
#   something large (like 86400, for one notification
#   per day).
#
LoginTimeout    86400

###### Open Portal settings.
#
##
# HomePage -- The authservice's notion of a default
#   redirect.
#
HomePage    http://nocat.net/

# DocumentRoot -- Where all of the application templates (including
#   SplashPage) are hiding. Can be different from Apache's DocumentRoot.
#   Defaults to /usr/local/share/NoCatSplash/htdocs via compile-time option.
#
# DocumentRoot    /usr/local/share/NoCatSplash/htdocs   

# SplashForm -- Form displayed to users on capture.
#
SplashForm    splash.html

# StatusForm -- Page displaying status of logged in users.
#   NOT YET IMPLEMENTED.
#
StatusForm    status.html

# SplashURL -- URL to fetch remote splash page from. You must compile
#   with --with-remote-splash for this to work. SplashTimeout specifies
#   the reload period of the remote splash page.
#
# SplashURL    http://example.com/get_splash_page.cgi?node=$NodeID
#
# SplashTimeout    21600

###### Active/Passive Portal settings.
# None of these settings affect open mode operation.
#
# TrustedGroups - A list of groups registered with the auth server
#   that a user may claim membership in order to gain Member-class
#   access through this portal. The default magic value "Any" indicates
#   that a member of *any* group is granted member-class access from
#   this gateway. NOT YET IMPLEMENTED.
#
# TrustedGroups    NoCat NYCWireless PersonalTelco
#
TrustedGroups Any

##
# Owners - Optional.  List all local "owner" class users here, separated
#   by spaces.  Owners typically get full bandwidth, and unrestricted
#   access to all network resources. NOT YET IMPLEMENTED.
#
# Owners [email protected] [email protected]

##
# AuthServiceAddr - Required, for captive mode. Must be set to the 
address of
#   your authentication service. You must use an IP address
#   if DNS resolution isn't available at gateway startup.
#
# AuthServiceAddr 208.201.239.21
#
AuthServiceAddr    auth.nocat.net

##
# AuthServiceURL - HTTPS URL to the login script at the authservice.
#
AuthServiceURL  https://auth.nocat.net/cgi-bin/login

##
# LogoutURL - HTTP URL to redirect user after logout.
#
LogoutURL    https://auth.nocat.net/logout.html

##
# PGPKeyPath -- The directory in which PGP keys are stored.
#   NoCat tries to find this in the pgp/ directory above
#   the bin/ parent directory. Set this only if you put it
#   somewhere that NoCat doesn't expect.
#
# PGPKeyPath    /usr/local/share/NoCatSplash/pgp


### Network Topology
#
# FirewallPath - Where to find the firewall scripts.
#   Defaults to /usr/local/libexec/NoCatSplash via compile-time option.
#
# FirewallPath    /usr/local/libexec/NoCatSplash

#
# ExternalDevice - Required if and only if NoCatAuth can't figure it out
#   from looking at your routing tables and picking the interface
#   that carries the default route. Must be set to the interface
#   connected to the Internet. Usually 'eth0' or 'eth1'
#   under Linux, or maybe even 'ppp0' if you're running
#   PPP or PPPoE.
#
ExternalDevice    eth0

##
# InternalDevice - Required if and only if your machine has more than two
#   network interfaces. Must be set to the interface connected to your local
#   network, normally your wireless card.
#
InternalDevice    eth1

##
# LocalNetwork - Required if and only if NoCatSplash can't figure it out
#   by polling the InternalDevice. Must be set to the network
#   address and net mask of your internal network. You
#   can use the number of bits in the netmask (e.g. /16, /24, etc.)
#   or the full x.x.x.x specification.
#
# LocalNetwork    10.0.1.0/24
LocalNetwork 192.168.2.0/24
##
# DNSAddr - Optional. *If* you choose not to run DNS on your internal 
network,
#   specify the address(es) of one or more domain name server on the 
Internet
#   that wireless clients can use to get out. Should be the same DNS 
that your
#   DHCP server hands out.
#
# DNSAddr 111.222.333.444
DNSAddr 196.3.81.5 200.88.127.22

##
# AllowedWebHosts - Optional.  List any domains that you would like to
#   allow web access (TCP port 80 and 443) BEFORE logging in (this is the
#   pre-'skip' stage, so be careful about what you allow.)
#
# AllowedWebHosts    nocat.net

##
# RouteOnly - Required only if you DO NOT want your gateway to act as a 
NAT.
#   Uncomment this only if you're running a strictly routed network, and
#   don't need the gateway to enable NAT for you.
#
# RouteOnly    1

##
# MembersOnly - Optional.  Uncomment this if you want to disable public
#   access (i.e. unauthenticated 'skip' button access).  You'll also want to
#   point AuthServiceURL somewhere that doesn't include a skip button (like
#   at your own Auth server.)
#
# MembersOnly    1

##
# IncludePorts - Optional.  Specify TCP ports to allow access to when
#   public class users login.  All others will be denied.
#
#   For a list of common services and their respective port numbers, see
#   your /etc/services file. Depending on your firewall, you might even
#   be able to specify said services here, instead of using port numbers.
#
# IncludePorts    22 80 443

##
# ExcludePorts - Optional.  Specify TCP ports to denied access to when
#   public class users login.  All others will be allowed.
#
#   Note that you should use either IncludePorts or ExcludePorts, but not
#   both.  If neither is specified, access is granted to all ports to
#   public class users.
#
#   You should *always* exclude port 25, unless you want to run an portal
#   for wanton spam sending. Users should have their own way of sending
#   mail. It sucks, but that's the way it is. Comment this out *only if*
#   you're using IncludePorts instead.
#
# ExcludePorts 23 25 111
#
ExcludePorts    25

####### Syslog Options -- alter these only if you want NoCat to log to the
#        system log! NOT YET IMPLEMENTED.
#
# Log Facility - syslog or internal.  Internal sends log messages
#    using the GatewayLog or STDERR if GatewayLog is unset.  Syslog
#    sends all messages to the system log.
#
# LogFacility    internal

##
# SyslogSocket - inet or unix.  Inet connects to an inet socket returned
#    by getsrvbyname().  Unix connects to a unix domain socket returned by
#    _PATH_LOG in syslog.ph (typically /dev/log).  Defaults to unix.
#
# SyslogSocket unix

##
# SyslogOptions - Zero or more of the words pid, ndelay, cons, nowait
#    Defaults to "cons,pid".
#
# SyslogOptions cons,pid

##
# SyslogPriority - The syslog class of message to use:  In decreasing 
importance,
#    the typical priorities are EMERG, ALERT, CRIT, ERR, WARNING, 
NOTICE, INFO,
#    and DEBUG.  Defaults to INFO.
#
# SyslogPriority INFO

##
# SyslogFacility - The facility used to log messages.  Defaults to user.
# SyslogFacility user

##
# SyslogIdent - The ident of the program that is calling syslog.  This will
#    be prepended to every log entry made by NoCat.  Defaults to NoCat.
#
# SyslogIdent NoCat

###### Other Common Gateway Options. (stuff you probably won't have to 
change)
#
# ResetCmd, PermitCmd, DenyCmd -- Shell commands to reset,
#   open and close the firewall. You probably don't need to
#   change these.
#
# ResetCmd    initialize.fw
# PermitCmd    access.fw permit $MAC $IP $Class
# DenyCmd    access.fw deny $MAC $IP $Class

##
# GatewayPort - The TCP port to bind the gateway
#   service to. 5280 is de-facto standard for NoCatAuth.
#   Change this only if you absolutely need to.
#
GatewayPort     5280

##
#
# IdleTimeout -- How often to check the ARP cache, in seconds,
#   for expiration of idle clients. NOT YET IMPLEMENTED.
#
# MaxMissedARP -- How many times a client can be missing from
#   the ARP cache before we assume they've gone away, and log them
#   out. Set to 0 to disable logout based on ARP cache expiration.
#
MaxMissedARP 0
#
# IdleTimeout   300

### Fin!



Colin White wrote:
> Can't speak for nocatsplash but this was my approach for nocatauth...
>  
> 1. Make sure your gpg is the same version on the gateway AND the 
> access point. (I had to downgrade both versions of gpg). 
>  
> 2. Check location, ownership and file perms (600) of  trustedkeys.gpg.
>  
> 3. Set/sync system time/date on both the access point and gateway (if 
> the system time is way out, you'll have problems with pgp keys).
>  
> The mailing lists seems to suggest ~90% of login loops and redirect 
> failures stem from key or certificate problems.
>  
> 4. Turn on verbose logging on the AP and the gateway (from within the 
> nocat.conf)
>  
> 5.  tail -f, the apache access and ssl-error logs as well as the nocat 
> access point logs.
>  
> 6. Test, tweak and retest, while watching the logs. Then post any 
> logged error msgs back to this list.
> Good luck
>  
> Rgds
> Colin
>  
> On Mon, Nov 17, 2008 at 7:24 PM, Wilson Hernandez - MSD, S. A. 
> <[email protected] <mailto:[email protected]>> wrote:
>
>     Hello.
>
>     I'm glad I found a mailing list for NoCat, hopefully there are
>     still some users here.
>
>     I've been trying to get configure nocatsplash for about a month
>     now but, can't get it to work on a Etch. It captures the packet
>     but it doesn't' redirect to the requested page. Can anyone help me
>     with this please. Your assistance will be very appreciated.
>
>     Thanks in advanced for your help.
>
>     _______________________________________________
>     NoCat mailing list
>     [email protected] <mailto:[email protected]>
>     http://lists.nocat.net/mailman/listinfo/nocat
>
>
>
>
> -- 
> Colin A. White
> P : +1 605 940 5863
>
>

-- 
*Wilson Hernandez*
Presidente
829.848.9595
809.766.0441
www.msdrd.com <http://www.msdrd.com>
Conservando el medio ambiente